Emergent-Threat CVE Automation

How Guard automatically scans for high-severity CVEs, detects them in your environment, launches exploitation hunts, and delivers a three-stage notification sequence.

Emergent-Threat CVE Automation

Guard's emergent-threat pipeline closes the gap between a CVE becoming public and your team knowing whether it is exploitable in your environment. When a high-EPSS/CVSS CVE enters production scanning, Guard runs a fully automated sequence — no manual intervention required — and delivers ordered notifications at each decisive moment.


How the pipeline works

The pipeline has four stages that proceed automatically once a qualifying CVE is ingested.

1. Scanning-started broadcast

When a high-EPSS/CVSS Nuclei template reaches Guard's production scanner, all customers receive a notification confirming that Guard is actively scanning for that CVE. This broadcast serves as the baseline signal: you know coverage is live before any findings exist.

2. Detection notification

If the CVE is found in your environment, your tenant receives a targeted detection alert correlated to the earlier broadcast. This notification is distinct from standard new-risk notifications so you can immediately distinguish an emergent-threat finding from routine discovery.

3. Automatic Hannibal exploitation hunt

On detection, Guard automatically launches a Hannibal exploitation hunt scoped to the affected finding. No manual scheduling or configuration is needed. The hunt attempts to prove whether the vulnerability is exploitable under real-world conditions.

4. Exploitation-proven notification

If Hannibal successfully exploits the vulnerability and captures evidence, your tenant receives a definitive exploitation-proven notification. This notification confirms the risk is not theoretical — Guard has demonstrated impact in your environment.


Notification summary

Stage

Recipient

Trigger

Scanning started

All customers

High-EPSS/CVSS Nuclei template reaches production

CVE detected

Affected tenant

CVE found in the tenant's environment

Exploitation proven

Affected tenant

Hannibal captures exploitation evidence


What to do at each stage

Scanning started No immediate action is required. Use this notification to confirm awareness of the CVE and begin internal triage if the technology is present in your environment.

CVE detected Review the correlated finding in Guard. Assess exposure scope and begin prioritizing remediation. The Hannibal hunt has already launched automatically — exploitation evidence may follow.

Exploitation proven Treat the finding as confirmed critical. Guard has captured evidence that the vulnerability is exploitable in your environment. Escalate according to your incident-response process and use the evidence in Guard to support remediation prioritization.


Qualifying CVEs

Guard selects CVEs for emergent-threat processing based on a combination of EPSS (Exploit Prediction Scoring System) and CVSS scores. Only CVEs that meet the high-severity threshold on both dimensions, and for which a production-quality Nuclei template is available, enter the automated pipeline.


Relationship to other Guard modules

  • Attack Surface Management — the scanner that performs detection draws on your continuously maintained attack surface inventory.
  • Breach and Attack Simulation (Hannibal) — exploitation hunts launched by this pipeline use the same Hannibal engine available for manual scheduling; see Breach and Attack Simulation for details on evidence capture and reporting.
  • Vulnerabilities — detections surfaced by the emergent-threat pipeline appear in the Vulnerabilities module and are labeled to indicate their emergent-threat origin.